[MAVEN:GHSA-83X4-9CWR-5487] Improper Authorization in Keycloak

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

A incorrect authorization flaw was found in Keycloak 12.0.0, the flaw allows an attacker with any existing user account to create new default user accounts via the administrative REST API even where new user registration is disabled.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services < 15.1.1
Package Fixed Version
pkg:maven/org.keycloak/keycloak-services = 15.1.1
ID
MAVEN:GHSA-83X4-9CWR-5487
Severity
high
URL
https://github.com/advisories/GHSA-83x4-9cwr-5487
Published
2022-01-06T18:32:58
(2 years ago)
Modified
2023-02-03T05:04:06
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 15.1.1
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 15.1.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...